Configuring Storefront Sites for B2C Commerce
New sites require some level of access control. Many use a single shared password for all users. Using a Business Manager login with the functional permission provides a much higher level of security and access control, in particular with frequent password renewals and employees leaving an organization.
Required Editions
| Available in: B2C Commerce |
For any services requiring access to the protected site, a Business Manager login is also strongly recommended. However, if the password expiration cycle is problematic, the shared password option provides a low-maintenance access control mechanism.
-
In Business Manager, click App Launcher
, and then select AdminstratorSitesManage
Sites.
Use the sort buttons to sort your sites. Sites appear in this order throughout the Business Manager user interface. - Click a site in the Storefront Sites table to manage an individual site.
-
On the General tab, configure the time zone, a
customer list, the brand, and billing entity.
See Site Time Zone and Site Brand and Billing Entity.
The ID, default currency, and taxation type are read only.
-
Click the Settings> tab.
Specify the cartridges and the cartridge path used by your site.
See Registering Your Cartridge.
The HTTP/HTTPS section has been deprecated. The preferred way to configure HTTP/HTTPS hostnames is in the site aliases configuration (SEO/Aliases Configuration). The HTTP/HTTPS hostnames values configured in this section apply if no hostnames are defined by aliases configuration, and are intended only to support the deprecated configuration style.
-
(Optional) Change the session timeout setting. The default is 30 minutes.
- In the Timeout field, enter a value between 15–120 minutes.
- Click the Cache tab.
-
Click the Site Status tab.
Access to non-production storefronts, for example, not yet live or residing on a different instance type (for example, staging/development) is typically protected by the storefront password protection.
When configuring access, you can provide a single user name/password set for everyone on the team. For a greater level of security, however, you can use Business Manager passwords. The benefit is that if a member leaves the team, their credentials can be deleted instead of having to redistribute a new set of credentials across the team.
- Select the Site Status: Maintenance, Online (Protected), or Online.
-
When you select Online (Protected), select one of
the following:
- Only users with the functional permission 'Access_Protected_Storefront': Only Business Manager users with the required functional permission Access_Protected_Storefront can log into the storefront. The storefront verifies that the credentials match a Business Manager user.
- Shared Password: Enter the username and password. All team members of the client staff or third-party teams who are eligible to access the storefront share this credential set.

